AOL 9.0 Disables Built In Firewall in XP SP1

From: A Wood (awood7_at_MSN.COM)
Date: 08/20/04

  • Next message: Robert E. Smith jr.: "SP2 Auto Update client incompatible with XPSP1 GPO Settings"
    Date:         Thu, 19 Aug 2004 19:45:54 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    I realize that this may be related to a home ISP product and may not exactly
    fall under business systems or IIS related products. However, chances are
    really great that you may have customers that are using AOL to connect to
    your networks from home.

    Keep in mind this problem only happens with AOL on Windows XP Service Pack 1
    Patched machines.

    Basically, the installation of AOL 9.0 disables the ability for users To
    configure the Built In firewall for Windows XP. Since the Firewall is
    turned off in XP SP1, by default, users are not able to turn on their
    firewall. The average user will not know about this problem and will assume
    that either 1) AOL will handle the problem (which they haven't) or Microsoft
    has taken care of the problem (which they haven't).

    To Duplicate the problem:

    1) Set up one XP Pro Box configured with SP1 and one XP Pro Box with SP2.
    Have both of these configured with a Dial-up Modem.
    2) Install AOL 9.0
    3) Try to configure the Firewall on the XP pro Boxes from the 'Network
    Connections' window. Typically, you would right click the Network
    Connection used to get to the internet and select properties.

    I have contacted Microsoft about this issue and their response was basically
    "It's not our problem". I have not been able to report this to AOL because
    they simply don't have any way to report this. Also, this issue has been
    reported to CERT.

    There are currently no fixes or workarounds for Systems Patched with Windows
    XP Service Pack 1 and there is no information on either AOL or Microsoft's
    web site on how to respond to this issue.

    With the Release of Windows XP service Pack 2 comes a newer firewall that is
    turned on by default. However, you still are not able to control the
    firewalls except for the workaround in the following KB article:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;870890

    Finally, this issue is so basic I can't believe that this problem made it
    past the last round of Beta testers at AOL before RTM.

    Aaron Wood
    Free Agent IT Dude
    Seattle, WA
    awood7@msn.com

    -----
    NTBugtraq Editor's Note:

    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    -----


  • Next message: Robert E. Smith jr.: "SP2 Auto Update client incompatible with XPSP1 GPO Settings"

    Relevant Pages

    • Re: Pornography on computer
      ... > I want this off my computer and I contacted AOL ... Beyond that - you need to clean up your PC and secure it. ... the built in Windows XP firewall because you use XP, ...
      (microsoft.public.windowsxp.hardware)
    • Re: Dialup Security: Is this a known problem?
      ... Even PC Magazine rated NIS and ZA at the top, ... > might be better served by using discreet tools: A firewall (use ... Sad that one must do so to keep the windows OS safe. ... Thst's common with AOL. ...
      (comp.security.firewalls)
    • Re: Missing Firewall in XP
      ... > I'm going to have to find a Firewall and install it since I can't seem to ... Ahh, AOL! ... Windows XP? ... If you have an America Online broadband Internet connection, ...
      (microsoft.public.security)
    • Re: AOL Broadband - I hear the moans already!!!
      ... teh Modem itself kept shutting down. ... > Apparently it's due to either the Software that AOL provided or the DSL ... Immediately turn-on Windows XP's built-in Firewall: ...
      (microsoft.public.windowsxp.network_web)
    • Re: 80072EFD after Download Box shows up and executes. AOL 9 & wi
      ... Noel Paton (MS-MVP 2002-2005, Windows) ... >> download the Stinger from here and run it to make sure that A-V-disabling ... IE will not work through AOL. ... IE through Earthlink; Can not download from Windows update ...
      (microsoft.public.windowsupdate)